Antivirus XP 2008 - Newest Malware On The Internet
87
Just so you're all aware there is a new malware being spread out on the net. I got hit with it earlier today visiting what looked like a legitimate video site.
It's called "Antivirus XP 2008" and is attached to a download of a codec pack that you are told is needed to view a video or picture.
(It may also be attached in a message that you need an ActiveX update)
It actually plants a constant image on a blue desktop (you lose your desktop image, if you have one) and a constant pop-up generates, telling you that a virus has been detected and directs you to a very good replica of a microsoft page that wants $50 - $100 for the Antivirus XP 2008 cure (depending on the package you purchase). It is a POS and also has to be removed.
Luckily, I figured it out before buying, but it still took me 4 hours to clean my folders, files, and registries. I also had to create a new registry to get back my screensaver and desktop background option tabs.
Below are some basic instructions for manually removing this malware. Please read carefully and perform at your own risk!
First you need to stop the program from loading on startup. This is what you do to stop it:
Click "Start," then, "run"
Type: msconfig
Go to Startup tab
Uncheck lphc35dj0e1an <----- These number/letters may be different
Uncheck rhc75dj0e1an <------- but will be similar to each other. Usually two that are very similar. These were taken from my computer.
Click: apply
Sponsored Links
- NOSTALGIA FINDER Remember what Mom threw away when you "grew up"? Wish you had it now? Now you can find it!
- SEARCH BEACON More than a search engine. Dating, Horoscopes, Shopping, and much more available!
- MILITARY INFO Find out what is happening around the world from military sources.
- EDUCATION INFO Need the top resources on Education? This site has it.
- CREDIT REPAIR The best site for fixing your credit reports and credit problems FAST!
- COMPUTERS A great resource for new and used computers, laptops, and even vintage equipment.
- iPHONES Need one? This site has a highly filtered search giving you just the phones without those who offer the unwanted codes.
Stop XP Antivirus 2008 Processes:
Access Processes by pressing Cont+Alt+Delete simultaneously (1 time)
(All below may or may not be present - stop any found)
vav.exe
XPAntivirus.exe
XPAntivirusUpdate.exe
xpa.exe
xpa2008.exe
Click: OK
Restart computer
Then you need to delete the main files this program uses. Delete the following files.
C:\windows\system32\lphc35dj0e1an.exe <------ Again, your .exe may be different than these!
C:\program files\rhc75dj0e1an\rhc75dj0e1an.exe
Also, do not forget to do a file and folder search...
Find and Delete these XP Antivirus 2008:
(may or may not be present)
xpa.exe
vav.exe
xpa2008.exe
XPAntivirus.exe
XPAntivirusUpdate.exe
XP antivirus
XPAntivirus.lnk
Uninstall XPAntivirus.lnk
XPAntivirus on the Web.lnk
XPAntivirus.url
XP Antivirus 2008.lnk
Uninstall XP Antivirus 2008.lnk
This should remove the program from your system but you probably still have a warning message displayed as your wallpaper in Windows and the virus removed the ability to change the wallpaper or your desktop settings.
To restore ability to change your desktop settings and select a different wallpaper and screen saver do the following:
Click: Start->Run->type: regedit ->click "OK"
Open the following folders\subfolders in order:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\
CurrentVersion\Policies\System
“System” being the last sub-folder.
create new entries:
1) a REG_DWORD entry called: NoDispBackgroundPage
2) a REG_DWORD entry called: NoDispScrSavPage
As long as their values are both set to 0, your tabs will be back.
Restart Computer
- Are you Tweaked, Twisted, or Torqued over what's happening around us? Join this brand new forum today! The Tweak Show
Share it! — Rate it: up down [flag this hub]
Comments
Hi Michelle,
I'd like to see the maker of this do some jail time. There must be law against it and the developer is obviosly profiting from the sale of the AV program. Jail time after I'm done giving him those baseball statistics with the bat, of course. :)
A forum friend also informed me it is also being spread by use of a message stating an ActiveX control is needed to be installed.
I'm aware that many people resort to wiping out an entire hard drive to remove this and other viruses. I'm hoping with this info, that won't be necessary. Doing a google search of "Antivirus XP 2008" will bring up sites that also explain how to manually uninstall this malware. Luckily, this is one that still gives you the ability to use the internet - though painstaking slowly.
HOLY SHIT THIS WORKED PERFECTLY!!!!!!!!1
cound'nt get my tabs back for desktop---added the reg values--then BANG!!--Didnt even have to RESTART---I just logged off/back on--!
THANK YOU HOMEBOY!!!!!!!!!!!!
Many thanks Bud! Ur method worked first time. Sorry I didnt find your assistance sooner!
Glad it worked for you both. :)
by far the best instructions for removal of antivirus xp 2008. my ISS (webroot) could not detect or eliminate the virus, however, this manual process did it all. you rock! thanks a ton.
Worked like a Charm. Thanks G! Highly recommended. I'd put ya up for computer Wiz of the Year any day.
Don't let the New World Order Form, don't fall for satans 666 (the Vchip) or allow the North American Union to furrther form. Abolish the Amero and Praise God almighty.
Thanks again
hi and thanks a lot ... had the same shitty xp , very good help to solve
Excellent advice. So far so good & the registry fix for the display & screensaver tabs worked perfect. Thanks for the post. It saved me a lot of time & suffering.
Makes me feel all warm and fuzzy knowing one of my hubs is doing some good! :)
I am from Singapore. I got hit by the same Malware 2 weeks ago. Could not solve the problem till I stumbled on to your website.
I did according to your approach and got rid of the "shit".
All I can say is 'THANK YOU.........."



Michelle says:
2 months ago
Sorry to hear you got hit by this, and thank you for the information, I am running XP. There are many times in the past I have been hit by viruses that have crashed my entire system, it was hell to rebuild the system and reinstall all of my software.
Wouldn't you love to have a baseball bat and a few minutes alone in a room with the &$$#*!% that created that virus! You could discuss baseball statistics or something....